[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4497-1] imagemagick security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4497-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                   Bastien Roucariès
March 11, 2026                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : imagemagick
Version        : 8:6.9.11.60+dfsg-1.3+deb11u10
CVE ID         : CVE-2026-24481 CVE-2026-24484 CVE-2026-24485 CVE-2026-25576 
                 CVE-2026-25638 CVE-2026-25795 CVE-2026-25796 CVE-2026-25797 
                 CVE-2026-25798 CVE-2026-25799 CVE-2026-25897 CVE-2026-25898 
                 CVE-2026-25965 CVE-2026-25968 CVE-2026-25970 CVE-2026-25982 
                 CVE-2026-25983 CVE-2026-25986 CVE-2026-25987 CVE-2026-25988 
                 CVE-2026-25989 CVE-2026-26066 CVE-2026-26283 CVE-2026-27798 
                 CVE-2026-27799

Multiple security vulnerabilities were discovered in imagemagick, a
software suite used for editing and manipulating digital images, which
could lead to information leaks, bypass of security policies, denial of
service or arbitrary code execution.

For Debian 11 bullseye, these problems have been fixed in version
8:6.9.11.60+dfsg-1.3+deb11u10.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmmx3ZYACgkQADoaLapB
CF+Nhg/9EZkeaP2R6B5i31pYzdUyYwvo9PrbnpSaGp2jrDkvCtgjS2ABY/rTBdb/
+QawI0Uuqk33LJS+UM9RHAPnMRClxmBuu8Ht5KRmIj6DayLO4IT8i/cqz7JEFGXV
jwTOt+wpQgF1xO/27CjY8LmNLzX81Gk/JS/ISxAPI5lhiJ4a9mgQHUmYU2xNognS
rjfJGhQfwacdBLSy9WV14EFYVPEcVo0vbh3EGlOJf7tUO7KUK5NRTQrVaWhq++9w
Iv7iEcp1/VMe1Jo1zbeKZDNzS6XiNXtyIPadiCXg0rjnetccCH/qUnXJZPMXd253
1bXREb1yFwD3N6DRpIgL9AB5l5LOMs+YjsPFzmwSv7Ifa6naXbVWnp3khEz1sviQ
OlO7P1KlUVmTrvs8UxQNLDVM0HKbn9uMzfqWMoA2XyWxwoaPLnUKgO8GbdH4VmDn
V40/oGW6kpd481HA2bd7W7/cZWr/aBzSteyct8el8d9ICKRSsu4afOVtNX6Awm0a
1HqCVltJuPqF3OrIVwmE1WwpyRk2pC71aFZGa/fqobro3+R9Vve8IOqoRvlzsW+k
KdJG+fBoyXfEAvkcCGGu71PMB5GcxMFWAlwcwizY0ZAwDnB54cxsO9J38bmnH7fT
Et8KtZZhFMU3pP901I7fQsqAtp/xP3Pgljvef0iSeqpSsEmkawQ=
=2ILn
-----END PGP SIGNATURE-----


Reply to: